Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to send arbitrary user-provided content to a third-party API, but it does not require explicit user notice or consent before transmitting that data off-platform. This creates a privacy and data-handling risk, especially if users provide sensitive URLs, tokens, contact info, or internal text expecting local processing.
